← Back

CVE-2024-32498

nvd nist
Published: Jul 5, 2024Modified: Nov 4, 2025

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected.

Affected (9)

3 products
Cinder
Glance
Nova
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Openstack
Before 22.1.3
From 23.0.0 to 23.1.1
Version 24.0.0
Openstack
Before 26.0.1
From 28.0.0 to 28.0.2
Version 27.0.0
Openstack
Before 27.3.1
From 28.0.0 to 28.1.1
From 29.0.0 to 29.0.3

References (9)

Source: cve@mitre.org
Issue TrackingPatch
Source: cve@mitre.org
Mailing ListPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatch

Timeline

No history available yet.